Ruby Bundler认证错误求助:bundle install提示需CGI转义用户名密码
Hey there, let's walk through troubleshooting this specific Bundler error you're hitting only in one code repo. The error is telling you that Bundler needs any usernames/passwords used for gem source authentication to be CGI-escaped—and even though you're using git:// for your GitHub gems, there are a few likely culprits here.
Possible Causes & Fixes
1. Check for hidden authenticated sources in your repo
Even if your Gemfile uses git:// URLs, double-check both:
- Your
Gemfilefor any gem sources that include credentials (likesource "https://user:password@rubygems.org"or a git gem with an HTTPS URL containing auth details) - Your
Gemfile.lock—sometimes lock files can retain old authenticated source entries from past installs, even if your Gemfile is updated. Try deletingGemfile.locktemporarily (make sure you can regenerate it safely) and runningbundle installagain.
2. Inspect your system/global Bundler config
Bundler might be pulling in global authentication settings that conflict with this repo. Run this command to see all active configs:
bundle config list
Look for entries like BUNDLE_GEM__SOURCE__HTTPS___RUBYGEMS_ORG or other source-specific auth settings. If you find any, you can delete them for the current repo with:
bundle config --delete <config-key>
Or clear all local repo configs entirely:
bundle config --delete
3. CGI-escape credentials if you need them
If you do have a gem source that requires authentication (even if it's not obvious), any special characters in your username or password (like @, :, #, /, or spaces) need to be CGI-escaped. For example:
@becomes%40#becomes%23:becomes%3A
So if your password is my@pass#123, the escaped version would be my%40pass%23123. Update your source URL to use this escaped string, like:
gem 'private-gem', git: 'https://username:my%40pass%23123@github.com/your-org/private-gem.git'
4. Address git:// limitations for private repos
git:// URLs don't support authentication natively. If the GitHub gems in question are private, Bundler might be silently falling back to HTTPS to access them—and if your global HTTPS auth credentials are unescaped, that triggers the error.
To fix this, either:
- Switch the gem URLs to use SSH (e.g.,
git@github.com:your-org/private-gem.git)—this avoids needing to manage credentials in URLs at all - Or update the URLs to use HTTPS with properly CGI-escaped credentials
内容的提问来源于stack exchange,提问作者jmknoll

